ÎÒÃÇÖ÷ÒªµÄÄ¿±êÊÇÍê³ÉÎļþ´Ó±¾µØ¼ÆËã»úÉÏ´«µ½·þÎñÆ÷ÉÏÈ¥¡£ÎªÁË×öµ½ÕâÒ»µã£¬ÎÒÃÇÐèÒª×öÒ»¸ö±í¸ñ£¬ÔÊÐíÓû§Ñ¡ÔñÒ»¸öÎļþ²¢¿ÉÒÔÌá½»Ëü¡£ÏÂÃæÊÇÒ»¸öÀý×Ó£º
<HTML>
<HEAD>
<TITLE>ÎļþÉÏ´«±í¸ñ</TITLE>
</HEAD>
<BODY>
<TABLE>
<FORM ENCTYPE="multipart/form-data" NAME=MyForm
ACTION=submit.php3
METHOD="POST">
<TR><TD>Ñ¡ÔñÉÏ´«Îļþ</TD><TD><INPUT NAME="MyFile"
TYPE="File"></TD></TR>
<TR><TD COLSPAN="2"><INPUT NAME="submit" VALUE="ÉÏ´«"
TYPE="submit"></TD></TR>
</TABLE>
</BODY>
</HTML>
×¢Òâ±í¸ñÖеÄENCTYPE="multipart/form-data"²¿·Ö¡£Õâ¸öÒ»¶¨²»ÄÜ´í£¬·ñÔò·þÎñÆ÷½«²»ÖªµÀÄãÔÚÉÏ´«Îļþ¡£
ÏÖÔÚÎÒÃÇÒѾÍê³ÉÁËǰ̨²¿·Ö£¬ÈÃÎÒÃÇÔÙ×ÐϸµØ¿¼ÂǺǫ́ÊÇÈçºÎ½ÓÊÕÎļþ²¢±£´æËüµ½ÎÒÃÇÖ¸¶¨µÄĿ¼ÏÂÈ¥¡£ÏÂÃæ¾Í¿ªÊ¼ÓÃPHPÁË¡£ÕâÊÇsubmit.php3µÄ³ÌÐò£º
<?
If($MyFile != "none") {
copy($MyFile,"/home/berber/$MyFile_name");
unlink($MyFile);
}
else {
echo"ÄãûÓÐÉÏ´«ÈκÎÎÄ?;
}
?>
²»¹ÜÄãÐŲ»ÐÅ£¬Õâ¾ÍÊÇÕû¸ö´¦Àí¹ý³Ì¡£ÎÒÃÇÔÚ³ÌÐòÖÐËù×öµÄ¾ÍÊÇ£º
1. ¼ì²éÊÇ·ñÒ»¸öÎļþÒѾÉÏ´«µ½·þÎñÆ÷£¬Í¨¹ýIf($MyFile != "none");
2. ¿½±´Îļþµ½Ö¸¶¨Î»Öá£
3. ɾ³ýÁÙʱÎļþ¡£
µ±Äã°´ÏÂÁËÌá½»°´Å¥ºó£¬Îļþ½«»á´ÓÄãµÄ¼ÆËã»úÉÏ´«µ½·þÎñÆ÷µÄÁÙʱĿ¼Ï¡£ÔÚÁÙʱĿ¼ÏµÄÎļþÃûΪһ¸öÁÙʱÎļþ¡£Ó¦¸ÃʹÓÃfile×ֶεÄnameÖµÀ´·ÃÎÊËü£¬ÔÚÕâÀïΪ$MyFile¡£ÕæÕýµÄÎļþÃûʹÓÃfile×ֶεÄnameÖµ¼ÓÉÏ"_name"À´·ÃÎÊËü£¬ÔÚÕâÀïΪ$MyFile_name¡£Ê¹ÓÃcopy()º¯Êý£¬½«ÁÙʱÎļþ$MyFile¿½±´µ½Ö¸¶¨Ä¿Â¼Ï£¬¿½±´ºóµÄÎļþÃûΪ$MyFile_name¡£Íê³Éºó²»ÒªÍüÁËɾ³ýÁÙʱÎļþ£¬²»È»Äã»áÓÐÐí¶àÄã²»ÏëÒªµÄÎļþ¡£
ÉèÖÃÎļþÃû
Ò»¸ö¿ÉÄÜÈóÌÐòԱ˯²»×žõµÄÊÂÇé¾ÍÊÇÊÔͼ¸Ä±äfile×ֶεÄVALUEÊôÐÔµÄÖµ¡£²¢²»ÊǺܶàÈËÖªµÀËüÊDz»¿ÉÄܵġ£¾¡¹ÜW3C˵¿ÉÒÔ£¬µ«Êµ¼ÊÉÏ£¬ÏóIEºÍNetscape¶¼²»ÔÊÐíÉèÖÃVAUEÊôÐÔµÄÖµ¡£ÌýÉÏÈ¥Óеã¿ÉЦ£¬ÎªÊ²Ã´ÎÒ²»ÄÜÉèÖÃÒ»¸ö³õʼֵ£¬ÕâÑùÈÃÓû§Ê¹ÓÃÆðÀ´¸ü·½±ãÄØ£¿Èç¹ûÄãÄÇÑù×ö£¬ÄÇÄã¾Í»á·¢ÏÖÄã´øÀ´ÁËÒ»¸ö°²È«ÉϵÄ©¶´¡£¿ÉÒÔÉèÏëһϣ¬ÄãµÇ¼µ½ÎÒµÄÍøÕ¾£¬ÎÒ¿ÉÒԸıäÒ»¸ö±í¸ñÖеÄfile×ֶεÄÖµ¡£
ÄÇôÓÐÐíÄÜ×èÖ¹ÎÒ°ÑÄãµÄ/etc/passwdÎļþÉÏ´«ÄØ£¿¸ü½øÒ»²½µÄ£¬ÎÒ²»ÐèÒªÄã°´ÏÂÌá½»°´Å¥£¬ÎÒ¿ÉÏÈÉèÖÃfile×ֶεÄÖµ£¬È»ºóͨ¹ýÒ»¶ÎJavaScript³ÌÐòÀ´Ä£ÄâÌá½»¶¯×÷...ÍÛÎØ...ÎÒ¿ÉÒÔ´¦ÀíÄã»úÆ÷ÉϵÄÈκÎÎļþÁË¡£ÒòΪÕâ¸öÔÒò£¬ä¯ÀÀÆ÷¼òµ¥µØ°Ñ<INPUT>±ê¼ÇÖеÄfile×ֶεÄVALUE×ֶθøºöÂÔÁË¡£
ÏÞÖÆÎļþ´óС
ÁíÒ»¸ö¿áµÄÌØÐÔÊÇÏÞÖÆÉÏ´«ÎļþµÄ´óСѡÏî¡£Ö»ÒªÔö¼ÓÒ»¸ö<INPUT>±ê¼Ç¾Í¿ÉÒÔÁË£º
<INPUT TYPE="hidden" name="MAX_FILE_SIZE" value="100000">
Õâ¸ö½«²»ÔÊÐíÓû§ÉÏ´«³¬¹ý100KBµÄÎļþ¡£
ÏÔʾÎļþ´óС
ΪÁËÏÔʾÎļþ´óС£¬¿ÉÒÔͨ¹ýfile×Ö¶ÎnameÊôÐÔÖµ¼ÓÉÏ"_size"Õâ¸ö±äÁ¿À´·ÃÎÊ¡£ÔÚÎÒÃǵÄÀý×ÓÖÐ
¾ÍÊÇʹÓÃ$MyFile_size¡£ËùÒÔ£¬Èç¹ûÄãÏë¸æËßÓû§ÉÏ´«ÎļþµÄ´óС£¬Äã¿ÉÒÔÏóÏÂÃæÄÇÑùÈ¥×ö£º
echo "You have just uploaded $MyFile_name";